Malware

Win32/Injector.EQZE malicious file

Malware Removal

The Win32/Injector.EQZE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EQZE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Exhibits behavior characteristics of GuLoader

How to determine Win32/Injector.EQZE?


File Info:

name: 13EFD15B4412789CBE86.mlw
path: /opt/CAPEv2/storage/binaries/cfe897ba4fcec3347df5fbdd6d54c5948c88de47ead4196618cb4f35817cebeb
crc32: B4CC8DA7
md5: 13efd15b4412789cbe865a1ead5026bc
sha1: 9659595715149d7ca22e5b5b775ca1b565d32e30
sha256: cfe897ba4fcec3347df5fbdd6d54c5948c88de47ead4196618cb4f35817cebeb
sha512: 337592569c7bd89e984f734d1305be823008c738f5941a6b7eb502af150254cea089f37b932fb181d503884460514e387f552060fbb0e8b4bfee41087030f882
ssdeep: 3072:n5/gd5/W06xtcO7R8gYWGABynqb7N9nMx6r:5/gbW0IR8AGABOqb7N9Mx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BC3B3266495B017D02285B13E63A7952CFAFD7B054CEA5F71CCEA0A533118F69A02FF
sha3_384: ff8c4b0f2deb83156278a8423383c419de651343c10ac6f50add5602db1f1d8809810e760e9124a62d9dbad87292f1d9
ep_bytes: 6808fc4000e8f0ffffff000000000000
timestamp: 2010-07-15 06:35:20

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Panopto
ProductName: Kaldsek3
FileVersion: 1.02
ProductVersion: 1.02
InternalName: dotards
OriginalFilename: dotards.exe

Win32/Injector.EQZE also known as:

LionicTrojan.Win32.Vebzenpak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38734042
FireEyeTrojan.GenericKD.38734042
McAfeeRDN/Generic.dx
ZillyaTrojan.Vebzenpak.Win32.4934
SangforTrojan.Win32.Vebzenpak.ahdd
K7AntiVirusTrojan ( 0058d80e1 )
K7GWTrojan ( 0058d80e1 )
CyrenW32/VBInject.AHT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EQZE
TrendMicro-HouseCallTROJ_GEN.R002C0PAT22
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vebzenpak.ahdd
BitDefenderTrojan.GenericKD.38734042
AvastWin32:Trojan-gen
EmsisoftTrojan.GenericKD.38734042 (B)
TrendMicroTROJ_GEN.R002C0PAT22
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ch
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.Nekark.tugly
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.3517CDB
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.GenericKD.38734042
CynetMalicious (score: 99)
VBA32BScope.TrojanSpy.Noon
ALYacTrojan.GenericKD.38734042
MalwarebytesTrojan.Injector
APEXMalicious
RisingBackdoor.Crysan!8.10ECA (CLOUD)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Kryptik.EQZE!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.EQZE?

Win32/Injector.EQZE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment